Skip to main content
Bibeno

Bibeno product

Everything your team needs to run each sale.

Explore Bibeno’s point-of-sale, product, stock and reporting tools.

Software overviewSee what Bibeno includes.Point of saleTake orders and complete sales at the counter.Products & menusManage products, prices and selling options.Inventory managementTrack stock movement and complete stock takes.Backoffice & reportingManage access and review business performance.Download for WindowsInstall Bibeno on a supported device.
Bibeno product catalog interface.Inside BibenoSee the full Bibeno product.Explore

Made for independent businesses

Software that fits the way your business works.

See how Bibeno supports food-service and specialty retail teams.

Industries overviewSee which businesses Bibeno is built for.CafésManage orders, products, stock and daily reporting.Takeaways and quick-serviceKeep service fast and every order organised.Boutiques and specialty retailManage checkout, products and stock together.
A café team serving a customer at the counter.Find the right fitTell us how your business operates.Explore
Pricing

About Bibeno

A South African team focused on independent business.

Learn about Bibeno, how we help businesses get started and how to contact us.

About BibenoOur story, purpose and product principles.How we workSee what to expect from setup and rollout.Contact usSpeak to sales, support or our general team.Get startedTell us about your business and what you need.
A team of independent bakery operators working together.Meet BibenoBuilt locally. Supported by real people.Explore
Sign inBook a demo
Legal/Subprocessor List

Subprocessor List

The controlled disclosure of third parties authorised to process customer-controlled personal information for Bibeno, including purpose, information, people, locations, onward processing, safeguards, retention, and change rights.

Status: Effective 14 August 2026Version: 1.0.0Content hash: 75f988abae16b84eca3e812302b9b907d2c54404f7945d0d259bb07b5f3383eb
1. Status and publication boundary0% read

On this page

Subprocessor List

  1. 1. Status and publication boundary
  2. 2. What this list covers
  3. 3. Information required for each approved provider
  4. 4. Provider categories requiring verification
  5. 5. Customer-selected providers
  6. 6. New and replacement providers
  7. 7. International processing and onward changes
  8. 8. History and contact

1. Status and publication boundary

This version does not represent an unverified provider as an approved production subprocessor. A provider may process customer-controlled personal information only after Bibeno has verified the provider's identity, role, service, information categories, locations, transfer safeguard, contract, security, retention, onward-processing, incident, and exit evidence in the controlled vendor register. Unverified providers and the processing that depends on them remain disabled by the applicable operational gate.

A provider name detected in configuration, source code, an invoice, a development environment, or a marketing page is not sufficient evidence that the provider is enabled, contracted, located in a particular region, or approved to process production personal information.

2. What this list covers

A subprocessor or sub-operator is a third party engaged by Bibeno to process customer-controlled personal information in Bibeno's operator role. Providers acting only for Bibeno's own responsible-party purposes, independent payment parties, customer-selected providers, and disabled providers are identified separately where that distinction is material.

The Data Processing Agreement governs authorisation, contracting, monitoring, international processing, incidents, assistance, audit evidence, and exit. This list supplies the current provider-specific facts and must be read with that agreement and the Security Measures Schedule.

3. Information required for each approved provider

  • Exact legal entity and service name, provider role, contract owner, and service purpose.
  • Categories of personal information and data subjects processed, with optional features distinguished from core processing.
  • Primary storage, processing, backup, failover, telemetry, and support-access countries or regions.
  • Authorised onward subprocessors or a verified route to the current onward-provider list.
  • POPIA section 72 or other approved international-transfer safeguard and its controlled evidence identifier.
  • Security, privacy, incident, deletion, retention, business-continuity, audit, and customer-assistance commitments.
  • Contract or DPA, security review, retention evidence, exit plan, approval date, evidence expiry, and last review date.
  • Whether the provider is mandatory, optional, customer-controlled, restricted to a feature or territory, or disabled.

4. Provider categories requiring verification

  • Frontend and application hosting, networking, content delivery, domains, and DNS.
  • Backend compute, databases, object and file storage, backups, queues, and scheduled operations.
  • Subscription payment processing, invoicing support, fraud controls, and provider transaction records.
  • Transactional email, customer-configured email or SMS, support communications, and message-delivery evidence.
  • Error monitoring, security telemetry, product analytics, performance diagnostics, and alerting when enabled.
  • Support ticketing, attachment storage and malware scanning, privacy requests, and security-incident operations.
  • App distribution, device services, customer-selected integrations, and any future identity, automation, or AI provider.

The public list contains only categories that are actually enabled in the approved production architecture and identifies optional processing clearly. A configured category may not be omitted from the controlled register even if its provider is still unverified or disabled.

5. Customer-selected providers

A customer may connect its own email, SMS, payment, storage, identity, or other provider. The customer selects and contracts with that provider and is responsible for its lawful basis, notices, settings, regions, retention, recipients, and exit. The provider does not become Bibeno's subprocessor merely because Bibeno supports a connection.

Bibeno remains responsible for the supported integration boundary: authentication, minimum data exchange, tenant and branch scoping, secure transport, failure handling, logs, revocation, deletion, and preventing a customer-selected provider from receiving information outside the customer's instruction.

6. New and replacement providers

Bibeno gives reasonable advance notice of a new or replacement subprocessor where the change materially affects customer-controlled information. The notice identifies the provider, purpose, information, people, locations, transfer safeguard, expected date, and objection route.

A customer may make a reasoned data-protection objection during the stated period. Bibeno will assess the risk and a reasonable alternative such as configuration, regional option, provider replacement, optional-feature disablement, or termination of the affected service. An objection is not accepted merely to avoid an unrelated commercial obligation.

An urgent security replacement may occur on shorter notice where delay would materially increase risk. Bibeno records the reason, completes the same verification, and provides notice as soon as reasonably possible.

7. International processing and onward changes

An international location or remote support route is approved only with a valid POPIA section 72 safeguard and current evidence. A provider may not silently add a processing region, support location, or onward subprocessor outside the approved boundary.

Bibeno reviews material provider notices and updates this list and the controlled register before the change is relied on for production processing. Where an onward change alters risk materially, Bibeno applies the same customer notice and objection process.

8. History and contact

Each published list is immutable and has a version and resolved-content hash. The version history preserves added, removed, and materially changed providers and whether a customer notice or re-acceptance was required.

Provider, location, transfer, and objection questions may be sent to support@bibeno.co.za or through the authenticated support route. Bibeno may provide additional confidential assurance under suitable protections but does not disclose provider secrets, another customer's information, or privileged material.

Book a demo
Bibeno

Point of sale and business management software for South African food-service and independent retail businesses.

Book a demo

Product

Software overviewIndustriesPricingDownload for WindowsBook a demoGet started

Company

AboutContact usSign in

Legal

Legal centreTermsPrivacyData processing agreementRefunds and cancellation
BIBENO (PTY) LTD · Reg. 2026/355321/07© 2026 Bibeno POSsupport@bibeno.co.za+27 60 659 1848

Choose your cookie preferences

Essential storage is always active. Optional analytics and marketing tools remain off unless you allow them. Read more.

Cookie preferences

Control optional website technologies

Necessary technology is always active. Optional categories remain off until you enable them. You can change these choices from the website footer.

Strictly necessary

Remembers your consent choice and supports essential website security and forms. This category cannot be switched off.

Currently used: Bibeno consent storage; Cloudflare Turnstile on protected demo forms.

Functional

Would remember optional site preferences that are not needed for core features.

Not currently used.

Analytics

Would help us understand website use and improve performance through approved measurement tools.

Not currently used.

Marketing

Would support approved advertising, campaign measurement or personalised marketing.

Not currently used.

Your browser is sending a Global Privacy Control signal. Optional categories remain off unless you actively change them here.